diff --git a/atomics/T1543.003/T1543.003.yaml b/atomics/T1543.003/T1543.003.yaml index 338b07ac..5e1f6018 100644 --- a/atomics/T1543.003/T1543.003.yaml +++ b/atomics/T1543.003/T1543.003.yaml @@ -92,6 +92,7 @@ atomic_tests: try {(Get-WmiObject Win32_Service -filter "name='#{service_name}'").Delete()} catch {} - name: TinyTurla backdoor service w64time + auto_generated_guid: ef0581fd-528e-4662-87bc-4c2affb86940 description: | It's running Dll as service to emulate the tine turla backdoor diff --git a/atomics/used_guids.txt b/atomics/used_guids.txt index 7aff52be..f27565b5 100644 --- a/atomics/used_guids.txt +++ b/atomics/used_guids.txt @@ -850,3 +850,4 @@ c510d25b-1667-467d-8331-a56d3e9bc4ff deecd55f-afe0-4a62-9fba-4d1ba2deb321 d239772b-88e2-4a2e-8473-897503401bcc eb8da98a-2e16-4551-b3dd-83de49baa14c +ef0581fd-528e-4662-87bc-4c2affb86940